Skip to content

Commit 8e426bb

Browse files
matrixiseclaude
andcommitted
fix(deps): upgrade pillow to 12.3.0 for security fixes
Resolves multiple high/medium severity Dependabot alerts: heap out-of-bounds writes in ImageCmsTransform.apply(), Image.paste()/crop() and ImageFilter.RankFilter, a JPEG2000 tiled-decode DoS, a decompression bomb in PdfParser, a TGA RLE encoder heap data leak, an OS command injection in WindowsViewer.get_command(), several decompression-bomb check bypasses (GdImageFile, BdfFontFile, FontFile, PcfFontFile), an out-of-bounds read via row stride on the mmap path, and an infinite loop DoS in EpsImagePlugin. GHSA-9hw9-ch79-4vh6, GHSA-vjc4-5qp5-m44j, GHSA-jjj6-mw9f-p565, GHSA-6r8x-57c9-28j4, GHSA-fj7v-r99m-22gq, GHSA-xj96-63gp-2gmr, GHSA-4x4j-2g7c-83w6, GHSA-phj9-mv4w-65pm, GHSA-45hq-cxwh-f6vc, GHSA-5x94-69rx-g8h2, GHSA-8v84-f9pq-wr9x, GHSA-62p4-gmf7-7g93, GHSA-pg7v-jwj7-p798 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
1 parent f5cbf26 commit 8e426bb

2 files changed

Lines changed: 2 additions & 2 deletions

File tree

‎requirements/dev.txt‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -140,7 +140,7 @@ packaging==26.2
140140
# pip-audit
141141
# pip-requirements-parser
142142
# pipdeptree
143-
pillow==12.2.0
143+
pillow==12.3.0
144144
# via
145145
# -c requirements/main.txt
146146
# pillow-heif

‎requirements/main.txt‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -117,7 +117,7 @@ packaging==26.2
117117
# via gunicorn
118118
pandas==3.0.3
119119
# via -r requirements/main.in
120-
pillow==12.2.0
120+
pillow==12.3.0
121121
# via
122122
# pillow-heif
123123
# wagtail

0 commit comments

Comments
 (0)